4 ms·
Yep, users made it clear that they can't be trusted to make such decisions, so now the apps have to comply with new requirements, including security audits by 3
by ucaetano 8y ago
Yep, users made it clear that they can't be trusted to make such decisions, so now the apps have to comply with new requirements, including security audits by 3rd parties.
- tptacek 8y agoWhich is totally sensible. Nobody believes end-users are qualified to assess the security risks of the applications they're opting into. It's a little like being angry at how expensive it is to inspect and qualify an airliner before allowing people to book flights on it.
- freedomben 8y agoWhat are end-users qualified to assess? Should we be able to choose what we want to eat if we aren't qualified nutritionists? People that aren't experts will certainly make poor decisions sometimes, or think they are choosing healthy food when it really isn't. Where do you draw the line?
- ac29 8y agoI think Google actually has taken more or less the right stance here. I'm not entirely sure that most people understand the difference between "click this button to make my app work" and "click this button to make my app work, and oh by the way you are also agreeing to let us sell your data to a marketing firm". Clarifications like the below are good for the vast majority of users (your opinion about Google's own business model aside): "3rd-party apps accessing these APIs must use the data to provide user-facing features and may not transfer or sell the data for other purposes such as targeting ads, market research, email campaign tracking, and other unrelated purposes. (Note: Gmail users’ email content is not used for ads personalization.) As an example, consolidating data from a user’s email for their direct benefit, such as expense tracking, is a permitted use case. Consolidating the expense data for market research that benefits a third party is not permitted. We have also clarified that human review of email data must be strictly limited." [0] [0] https://cloud.google.com/blog/products/g-suite/elevating-user-trust-in-our-api-ecosystems https://cloud.google.com/blog/products/g-suite/elevating-use...
- DEADBEEFC0FFEE 8y agoIf your a company you draw the line somewhere near where your lawyers and accountants tell you to, on behalf of shareholders.
- p1mrx 8y agoThere should be a requirement to publish an easily-understandable description of what the app does with its Gmail access. Pay $x per year to an auditor who verifies the description. As long as the [I agree] section says "We send all your email to market researchers for money", then it's fair game to publish.
- freedomben 8y agoI could definitely get on board with that. My only concern is that the expense if paying a professional auditor might make startups and individuals and open source projects unable to compete, but there could be solutions to those problems.
- TeMPOraL 8y agoThat's basically (a subset of) GDPR, except here implement by Google to protect themselves from another CA scandal.
- solarkraft 8y ago> Nobody believes end-users are qualified to assess the security risks of the applications they're opting into Maybe not. Probably not. But I sure know I don't want to lose any freedom. Can this be mitigated with custom-generated API keys?